Courseiva
vSphere SecuritymediumMultiple SelectObjective-mapped

VCP-DCV vSphere Security Practice Question

Which TWO of the following are best practices for securing a vSphere environment against ransomware attacks?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a backup solution with immutable snapshots and offsite storage.

The correct answers are A and D. Implement a backup solution with immutable snapshots and offsite storage (A) ensures backups cannot be deleted or encrypted by ransomware, enabling recovery. Enabling vSAN encryption (D) protects data at rest, preventing unauthorized access if storage is compromised. Option B is wrong because vMotion encryption protects data in transit during migration, not against ransomware. Option C is wrong because VM snapshots are not backups; they can be deleted by ransomware and do not provide long-term recovery. Option E is wrong because allowing all outbound traffic by default violates the principle of least privilege and increases attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement a backup solution with immutable snapshots and offsite storage.

    Why this is correct

    Immutable backups protect against ransomware altering or deleting backups.

  • Enable vMotion encryption for all migrations.

    Why it's wrong here

    vMotion encryption protects in-transit data but does not prevent ransomware attacks.

  • Use VM snapshots as primary backup method.

    Why it's wrong here

    Snapshots are not backups; they can be deleted and do not provide immutable protection.

  • Enable vSAN encryption to protect data at rest.

    Why this is correct

    Encryption protects data even if storage is accessed.

  • Configure the distributed firewall to allow all outbound traffic by default.

    Why it's wrong here

    Best practice is to deny by default and allow only necessary traffic.

About these practice questions

One of 498 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.